CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 13 of 126
- CVE-2016-6331HIGHCVSS 7.5EG 7.52017-04-20
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
- CVE-2016-6336MEDIUMCVSS 6.5EG 6.52017-04-20
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion statu…
- CVE-2016-6337HIGHCVSS 7.5EG 7.52017-04-20
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
- CVE-2016-6338MEDIUMCVSS 6.8EG 6.82017-04-20
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selection…
- CVE-2016-6342HIGHCVSS 7.5EG 7.52017-06-27
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
- CVE-2016-6543MEDIUMCVSS 5.9EG 5.92018-07-13
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.
- CVE-2016-6598CRITICALCVSS 9.8EG 9.82018-01-30
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is run…
- CVE-2016-6605HIGHCVSS 7.5EG 7.52017-04-10
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
- CVE-2016-6690MEDIUMCVSS 5.5EG 5.52016-10-10
The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot) via a crafted application, aka internal bug 28838221.
- CVE-2016-6701HIGHCVSS 7.8EG 7.82016-11-25
A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to …
- CVE-2016-6702HIGHCVSS 7.8EG 7.82016-11-25
A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged pr…
- CVE-2016-6703HIGHCVSS 7.8EG 7.82016-11-25
A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker using a specially crafted payload to execute arbitr…
- CVE-2016-6708MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypa…
- CVE-2016-6713MEDIUMCVSS 5.5EG 5.52016-11-25
A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due t…
- CVE-2016-6714MEDIUMCVSS 5.5EG 5.52016-11-25
A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due t…
- CVE-2016-6715MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio w…
- CVE-2016-6716MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create shortcuts that have elevated privileges without the user's consent. This issue is rated as Mo…
- CVE-2016-6719MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to pair wit…
- CVE-2016-6723MEDIUMCVSS 4.7EG 4.72016-11-25
A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a specially crafted file to …
- CVE-2016-6724MEDIUMCVSS 5.5EG 5.52016-11-25
A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the de…
- CVE-2016-6725CRITICALCVSS 9.8EG 9.82016-11-25
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibil…
- CVE-2016-6747MEDIUMCVSS 5.5EG 5.52016-11-25
A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of…
- CVE-2016-6755HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising…
- CVE-2016-6758HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain …
- CVE-2016-6759HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain …
- CVE-2016-6760HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain …
- CVE-2016-6761HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain …
- CVE-2016-6763MEDIUMCVSS 5.5EG 5.52017-01-12
A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of local permanent denial of ser…
- CVE-2016-6768HIGHCVSS 7.8EG 7.82017-01-12
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibil…
- CVE-2016-6769MEDIUMCVSS 4.6EG 4.62017-01-12
An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Sm…
- CVE-2016-6770LOWCVSS 3.3EG 3.32017-01-12
An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a c…
- CVE-2016-6771MEDIUMCVSS 5.3EG 5.32017-01-12
An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrain…
- CVE-2016-6775HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-6776HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-6777HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-6778HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising…
- CVE-2016-6779HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising…
- CVE-2016-6780HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising…
- CVE-2016-6781HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a priv…
- CVE-2016-6782HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a priv…
- CVE-2016-6783HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a priv…
- CVE-2016-6784HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a priv…
- CVE-2016-6785HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a priv…
- CVE-2016-6789HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could b…
- CVE-2016-6790HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could b…
- CVE-2016-6791HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-6802HIGHCVSS 7.5EG 7.52016-09-20
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
- CVE-2016-6807CRITICALCVSS 9.8EG 9.82017-03-28
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process …
- CVE-2016-6826MEDIUMCVSS 6.5EG 6.52016-09-26
Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.
- CVE-2016-6898MEDIUMCVSS 6.6EG 6.62016-09-07
XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary files or cause a denial of service (web se…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →